mirror of
https://github.com/finos/SymphonyElectron.git
synced 2025-02-25 18:55:29 -06:00
use --ignore-scripts on cve build
This commit is contained in:
2
.github/workflows/cve-scanning-node.yml
vendored
2
.github/workflows/cve-scanning-node.yml
vendored
@@ -22,5 +22,5 @@ jobs:
|
||||
node-version: ${{ matrix.node-version }}
|
||||
- run: npm config set package-lock false
|
||||
# TODO - this is ignoring package-lock.json
|
||||
- run: npm install --prod
|
||||
- run: npm install --prod --ignore-scripts
|
||||
- run: npx --yes auditjs ossi --whitelist allow-list.json
|
||||
Reference in New Issue
Block a user